Intel

AIKIDO-2026-11161

spring-webflux is vulnerable to Escalation via Session Fixation in WebFlux

Escalation via Session Fixation in WebFluxCVE-2026-41839 Published Yesterday

42

Medium Risk

This Affects:

JAVAspring-webflux
5.3.0 - 5.3.48
Fixed in 5.3.49
6.1.0 - 6.1.27
Fixed in 6.1.28
6.2.0 - 6.2.18
Fixed in 6.2.19
7.0.0 - 7.0.7
Fixed in 7.0.7.1
Are you affected? Scan for Free

TL;DR

A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-webflux is vulnerable to Escalation via Session Fixation in WebFlux in versions 5.3.0 - 5.3.48, 6.1.0 - 6.1.27, 6.2.0 - 6.2.18 and 7.0.0 - 7.0.7.

How to fix this

Upgrade the org.springframework:spring-webflux library to the patch version.